All problem statements
SIH26163SoftwareSmart Automation

Security Assessment of the World Monitor application

National Technical Research Organisation (NTRO)

Ideas submitted
26 / 500
Deadline
30 September 2026
Category
Software
Theme
Smart Automation

Looks like it needs

Mobile (Flutter / Android)IoT / EmbeddedCybersecurity

• Background The world Monitor application is a Web/ Mobile platform that provides users with real-time monitoring, analytics, and reporting features. The application handles user authentication, data visualization, API communication, and role-based access controls.

As a security analyst, the task is to evaluate the application's security posture and identify vulnerabilities that could compromise the confidentiality, integrity, or availability of the system.

• Description Conduct an authorized security assessment of the World Monitor application to:

1. Identify security vulnerabilities in the application.

2. Assess the potential impact of each vulnerability.

3. Demonstrate proof-of-concept exploitation in a controlled environment.

4. Recommend remediation measures to mitigate the identified risks.

• Scope The assessment should focus on: • Authentication and session management • Authorization and access control • Input validation and data handling • API security • Client-side security controls • Secure communication mechanisms • Data storage and privacy protections • Success Criteria The assessment is considered successful if: • At least one valid vulnerability is identified and documented. • Evidence supports the existence of the vulnerability. • Risk and impact are clearly explained. • Practical mitigation strategies are provided • Expected Solution/Deliverables:

For each vulnerability discovered, provide

• Vulnerability title • Description • Affected component • Severity rating (e.g., CVSS) • Steps to reproduce • Proof of concept demonstrating the issue in a safe testing environment • Business impact assessment • Remediation recommendations constraints • Testing must be performed only on authorized systems. • No actions should affect production users or data. • Exploitation should be limited to proof-of-concept validation. • Compliance with applicable laws, policies, and ethical hacking guidelines is required.

How contested this one is

as of 28 Sept
26ideas submitted+7 in 2 days

That puts it 226th of the 240 statements that have any ideas at all, out of 240 on the board. It is moving, so the field here is already forming.

See what the whole field is picking →

Counted from the official portal twice a day. The portal itself only shows today.

What a jury will ask about this

  1. 01“Who actually faces this problem today?”

    What works: Naming one real person and what they do instead right now. Reading the statement back is not an answer, they already read it.

  2. 02“This already exists. Why yours?”

    What works: That existing tools are consumer products. Yours is built for the ministry, works offline, in the local language, on official data.

  3. 03“Then why has nobody solved it yet?”

    What works: The real blocker. No connectivity, no incentive, nobody owns the data. You only know this if you read the ministry's own reports.

All 18 questions, with the trap answers →

More in Smart Automation

See all →